The short version
- Most tools run in your browser. Your files, text and drafts stay on your device.
- Analytics (Google Analytics and Microsoft Clarity) only start if you click Accept on the cookie notice.
- The contact form, the newsletter sign-up and the URL shortener send what you type to my server. P2P File Sharing passes only an encrypted pairing message through it; your files go straight to the other device. The other tools send nothing.
- On the free tool pages, a counter adds one to that tool's daily total, one more when you start using it, and the name of the site or page you came from. No cookies, no IP address and nothing that identifies you are kept.
- If I ask a client for a testimonial, what they write is kept privately and only shown on the site when they tick the box that allows it.
- A brief you send is saved in a private database before the email goes out, so I do not lose it. I delete it when it is no longer needed (see How long I keep it).
- The forms use Cloudflare Turnstile and a few simple checks to keep bots and spam out.
- I do not sell your data.
What I collect, and why
Analytics, only with your consent. Google Analytics 4 records page views, the device and browser you use, your approximate location and how you found the site. Microsoft Clarity records how you click, scroll and move around the page, as heatmaps and session replays. I use both to see which pages work and which are confusing. Clarity is switched off on pages where you type your own text or personal details, such as the notepad, invoice generator and resume builder.
Hosting logs. The site is hosted by Vercel. Like any host, Vercel sees your IP address and basic request details when you load a page. This is needed to run and protect the site. If Vercel Web Analytics is turned on, it counts visits without cookies.
Cookieless analytics. Every page loads Ahrefs Web Analytics, which counts page views, the page you came from, your browser and device type and your approximate country. It sets no cookies and stores nothing in your browser, so it does not need your consent and cannot follow you across sites. Ahrefs sees your IP address when the script loads, as any server does.
Messages and bookings. If you email me, send a brief or message me on WhatsApp, I get what you send and your contact details. If you book a call, Microsoft Bookings collects what you type into the form. I use this only to reply and to do the work you ask for.
The contact form. If you send a brief, I collect your name and email address, your message, and the company, website, service, budget and timeline if you fill them in. I also record that you agreed to this policy. Added automatically: the page you sent it from, the page you came from on this site (or the website you came from), the time, the result of the spam check, and whether the emails were delivered. I use all of this only to reply to you, to do the work you ask for, and to keep my own records.
Where a brief goes. It is saved in a private database (Upstash), and emailed to my mailbox (Microsoft 365) through Resend, an email delivery service. You get a confirmation email, also through Resend, with an unsubscribe link. The database copy is saved first, so your message is kept even if an email fails to deliver. Only I can open the stored briefs, from a password-protected page. I can download them as a spreadsheet for my own records.
Replies, quotes and my team. When I reply to a brief, the reply is kept with it. If I send you a quote, I keep the quote (what it covers, the price, the dates) and, if you open the quote page, whether you accepted or declined and when. A person I authorise to help me, such as a virtual assistant, may read briefs and reply to them from the same admin page. They cannot export, delete or change settings, and what each person does in the admin is recorded in a log I keep for security.
Alerts and backups. When a brief arrives I may get an alert on my phone, in Telegram or in Slack, with your name, the service you asked about, your budget and the first lines of your message. Each night a copy of the stored briefs is emailed to my own mailbox as a backup.
Whether my emails reach you. Resend, the service that sends my emails, tells my site what happened to each one: delivered, delayed, bounced, opened or reported as spam. I keep this for up to six months so I can tell if a reply of mine never arrived. If an address bounces for good or reports spam, I stop writing to it.
People who sign in to my admin. When I or someone I authorise signs in to the admin page, the site records the time, IP address, approximate location from the network, the location the browser shares (signing in requires it), the device and browser, language and time zone. This is for security, so I can see who is signed in and end a session. It concerns the people who work on my site, not visitors.
The newsletter. If you subscribe, I store your email address, and your first name if you choose to give it, in my private database. There is no confirmation step: you are subscribed straight away and get a short welcome email with an unsubscribe link, then, later, the emails I send. The forms that send me a brief have a separate box, “Also send me Aashish’s occasional newsletter”. It is unticked by default; only if you tick it do I add that address, and your first name, to the same list. A form never adds someone who has already unsubscribed. I also keep a record of your address, the page you signed up from, your status (subscribed or unsubscribed) and the dates, in my database. Every email has an unsubscribe link, and you can also reply to ask me to remove you.
The URL shortener. When you shorten a link, my server stores the link, the short code, the creation time and the expiry time, until it expires. It also counts clicks on each short link. To limit abuse, it counts requests per IP address for up to one hour and up to 24 hours.
P2P File Sharing. Files and messages you send with this tool go directly from your browser to the other device over an encrypted WebRTC connection. They never reach my server and I cannot see them. To pair two devices by code, each browser leaves one short message for the other on my server: the network addresses and connection settings the devices need to find each other. Your browser encrypts it first with a key made from the pairing code, and the code never leaves your device, so my server cannot read it. It is deleted as soon as the devices connect, and after 10 minutes at the latest. To limit abuse, my server counts how many codes each IP address makes, for up to one hour. To find its public address, your browser also contacts public STUN servers run by Google and Cloudflare, which see your IP address. Copy and paste pairing sends nothing to my server. Received files stay in your browser until you save them; large ones are kept in the browser's own storage for this site and cleared the next time you open the tool.
Spam and bot protection. The forms use Cloudflare Turnstile. When you use a form, your browser loads a script from Cloudflare, which looks at signals from your browser (such as your IP address) to tell people from bots. This is a security measure, so it runs whether or not you accept analytics. My server also scores each brief for signs of spam (for example many links, known spam phrases, a throwaway email address or a message posted from another website). A brief that looks like spam is saved with its score for me to review and is not emailed to me; if I got it wrong, write to me and I will find it. To stop floods, my server counts requests per IP address and per email address for up to 24 hours, and a short fingerprint of a message to spot repeats, which stays up to 24 hours. You can send the same brief up to three times a day.
Data that stays in your browser. The tools and the 3D site save drafts, settings and progress in your browser storage (for example your invoice or resume draft, your time zone list, and your ride progress). This is never sent to me. Clearing your browser data deletes it. Your cookie choice is saved the same way.
Others who see your data
These companies process data for me to run the site. Most are outside India, including in the United States, and each has its own privacy policy: Vercel (hosting), Upstash (the database that stores briefs, sign-ups, short links and the encrypted pairing messages of P2P File Sharing, hosted in Mumbai, India), Resend (delivering the emails from the contact form and newsletter), Microsoft (my email inbox and the Bookings page for calls), Cloudflare (the Turnstile bot check), Telegram or Slack (alerts, if I turn them on) Ahrefs (cookieless page view counts) and, if you accept analytics, Google and Microsoft Clarity. Loading a page also contacts Google Fonts (fonts), unpkg (some scripts, such as three.js and React) and Simple Icons (some logos), which see your IP address when they deliver files. P2P File Sharing contacts STUN servers run by Google and Cloudflare, which see your IP address. I do not sell your data and I do not share it for advertising.
On what basis
- Analytics: your consent. You can withdraw it at any time with the Cookie settings link in the footer.
- Hosting, security and abuse prevention: my legitimate interest in running a safe site.
- Cookieless page view counts (Ahrefs Web Analytics): my legitimate interest in knowing which pages are read.
- Replying to you and doing work you ask for: to take the steps you request. For the contact form you also give consent by ticking the box before you send.
- Spam and bot protection, and keeping a record of briefs: my legitimate interest in running a safe site and answering real enquiries.
- The newsletter: your consent, which you give by subscribing, or by leaving the newsletter box on a form ticked (you can untick it). You can withdraw it at any time by unsubscribing.
How long I keep it
- Briefs sent through the form, my replies, notes and any quote sent to you: up to 24 months after our last contact. If we work together, I keep what is needed for the work and for my accounts and tax records, as the law requires.
- Briefs the spam check flagged: up to 90 days, so I can rescue real ones.
- Short links and their click counts: until the link expires (one day to one year). Request counters and message fingerprints: up to 24 hours.
- P2P File Sharing pairing messages: until the two devices connect, and 10 minutes at most.
- Emails in my mailbox: as long as needed to deal with your request and to keep a record of the work.
- Newsletter address: until you unsubscribe. After that the address stays in my database, marked as unsubscribed, so I do not email you again by mistake. Ask me if you want it deleted completely.
- Analytics data stays in Google Analytics, Clarity and Ahrefs under their own retention settings.
- You can ask me to delete your data sooner at any time.
Your rights
Depending on where you live (for example under the GDPR, the UK GDPR or India’s Digital Personal Data Protection Act, 2023), you may have the right to see your data, correct it, delete it, object to how it is used, and withdraw consent. Write to me and I will reply within 30 days. To have a brief or your newsletter address deleted, email me from the address you used. You can also complain to your data protection authority. For India’s DPDP Act, the person to contact about any concern is me, Aashish Pandey, at hello@aashishpandey.com.
Keeping it safe
The site uses HTTPS. Stored briefs sit in a password-protected database and can be opened only by me. No system is perfectly secure. If a breach puts your data at risk, I will tell you and the authorities as the law requires.
Children
The site is not meant for children under 13, and I do not knowingly collect their data.
Changes
I may update this policy. The date at the top shows the latest version.
Contact
hello@aashishpandey.com. See also the cookie policy and the terms of use.